To detect if your iPhone is infected check your root password and SSH connection availability. If you can't connect to your device by SSH and your root password is 'alpine' (which is default) your fears are most likely justified. If you are still not sure, check if you have files like these: com.apple.ksyslog.plist and com.apple.period.
If the Ikee.b worm managed to intrude the system he will try to write his files to:
/BIN/POC-bbot
/BIN/sshpass or
/usr/libexec/cydia/startup
/usr/libexec/cydia/startup-helperAfter doing that he will change the background image:
/var/log/youcanbeclosertogod.jpg
/usr/libexec/cydia/startup.soAnd finally it writes the files into startup:
/System/Library/LaunchDaemons/com.ikey.bbot.plist
/System/Library/LaunchDaemons/com.saurik.Cydia.Startup.plistThat last action is needed for worm activation while next iPhone launch and for killing SSH access by deleting /bin/sshd.
You can easily delete the Ikee.b virus by simply deleting these folders:
/bin/poc-bbot
/bin/sshpass
/usr/libexec/cydia/startup
/usr/libexec/cydia/startup-helper
/var/log/youcanbeclosertogod.jpg
/usr/libexec/cydia/startup.so
/System/Library/LaunchDaemons/com.ikey.bbot.plist
After deleting those System/Library/LaunchDaemons/com.saurik.Cydia.Startup.plist should look like this:
Label com.saurik.Cydia.Startup Program /usr/libexec/cydia/startup RunAtLoadThat's it, your gadget is now virus free. Now you need to reinstall SSH and reboot iPhone. Remember that this worm is able to access your device only because of jailbreaking as the process disables all the defense from iPhone. So if you want to be safe it's better to be sure that you know what you're into.
Recent Blog
Ultimate Guide: How to turn Off Restricted Mode on iPhone?
Automate Apple GSX check result obtaining?
iRemove Unlock iPhone 5S, 5C, 5, SE, 4S/4 Software
MacOS High Sierra Features: Set Up Websites in Safari on Mac
How to Enable iOS 11 Mail Reply Notification on iPhone 7
How to Bypass Apple Watch Passcode Problem
LetsUnlock Services List
iPhone & iPad Activation Lock Bypass
Use LetsUnlock iCloud Tool to bypass Activation Lock Screen on iPhone and iPad running on iOS version up to 14.6.
Read More
Unlock Passcode Disabled iPhone or iPad
LetsUnlock iCloud Tool is ready to remove Find My and unlock your passcode disable device running on iOS 13.x.x in one click!
Read More
MacOS iCloud Activation Lock Bypass
The LetsUnlock Mac iCloud Activation Lock Bypass Tool will help you to remove Activation Lock on an iCloud locked Mac which is stuck on Activation Lock Screen with no need to enter the correct Apple ID and password.
Read More
Mac EFI Firmware Passcode Bypass
The LetsUnlock EFI Bypass Tool is a one button solution, which you click to start the EFI Unlock process. Bypass EFI with out password! Everything else does the software.
Read More
MacOS iCloud System PIN Bypass
The LetsUnlock MacOS iCloud System PIN Bypass Tool was designed to bypass iCloud PIN lock on macOS without passcode!
Read More